|
Log-Analyse und Auswertung: TR/Spy.ZBot.akt von Avira gefundenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
10.07.2013, 18:13 | #1 |
| TR/Spy.ZBot.akt von Avira gefunden Hallo! Ich habe gerade mal wieder einen Virensuchlauf laufen lassen und dabei wurde das Schadprogramm "TR/Spy.ZBot.akt" gefunden. Aus dem Avira Report: Beginne mit der Suche in 'C:\' <Acer> C:\Users\****\AppData\Local\Microsoft\Windows Live Mail\Gmx (phil_k 33d\Inbox\02164DC8-0000371F.eml [0] Archivtyp: MIME --> Rechnung **** vom 17.06.2013 Anwaltschaft Imwalking GmbH.zip [1] Archivtyp: ZIP --> Rechnung fur **** Inkasso Imwalking GmbH 17.06.2013.zip [2] Archivtyp: ZIP --> **** Aufforderung 17.06.2013 Inkasso Imwalking GmbH.com [FUND] Ist das Trojanische Pferd TR/Spy.ZBot.akt C:\Users\Philipp\AppData\Local\Opera\Opera x64\cache\g_005E\opr0HGR3.tmp [WARNUNG] Die Datei konnte nicht gelesen werden! Beginne mit der Suche in 'E:\' Der zu durchsuchende Pfad E:\ konnte nicht geöffnet werden C:\Users\XXXXXX\AppData\Local\Microsoft\Windows Live Mail\Gmx (phil_k 33d\Inbox\02164DC8-0000371F.eml [FUND] Ist das Trojanische Pferd TR/Spy.ZBot.akt [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '57052364.qua' verschoben! Ich erinnere mich an eine offensichtliche Betrugsmail mit seltsamem Anhang. Genau weiß ich es nicht mehr, aber ich bin mir ziemlich sicher, dass ich den nicht aufgemacht habe! Ich hab das Ding von Avira in die Quarantäne schicken lassen und würde gern wissen ob mein System infiziert ist, oder was ich mit dem Trojaner in der Quarantäne machen soll. Die Logs von Defogger, OTL und GMER habe ich angehängt. Könnt ihr mir helfen? |
10.07.2013, 18:14 | #2 |
/// the machine /// TB-Ausbilder | TR/Spy.ZBot.akt von Avira gefunden hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
10.07.2013, 18:21 | #3 |
| TR/Spy.ZBot.akt von Avira gefunden Wow, danke für die schnelle Antwort!
__________________Die Logs sind angehängt. FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-07-2013 01 Ran by Philipp (administrator) on 10-07-2013 19:18:07 Running from C:\Users\Philipp\Desktop Windows 7 Home Premium (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Acer Incorporated) C:\Program Files\Acer\Optical Drive Power Management\ODDPWRSvc.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe (Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe (AlcorMicro Co., Ltd.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Acer Incorporated) C:\Program Files\Acer\Optical Drive Power Management\ODDPWR.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe (Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Opera Software) C:\Program Files (x86)\Opera\15.0.1147.130\opera.exe (Opera Software) C:\Program Files (x86)\Opera\15.0.1147.130\opera.exe (Opera Software) C:\Program Files (x86)\Opera\15.0.1147.130\opera.exe (Opera Software) C:\Program Files (x86)\Opera\15.0.1147.130\opera.exe (Opera Software) C:\Program Files (x86)\Opera\15.0.1147.130\opera.exe (Opera Software) C:\Program Files (x86)\Opera\15.0.1147.130\opera.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [320000 2009-04-09] (AlcorMicro Co., Ltd.) HKLM\...\Run: [ODDPwr] - "C:\Program Files\Acer\Optical Drive Power Management\ODDPwr.exe" [223264 2010-04-22] (Acer Incorporated) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10775072 2010-04-22] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 [2040352 2010-04-22] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-17] (Synaptics Incorporated) HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe [496160 2010-04-23] (Acer Incorporated) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation) HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1300560 2010-03-03] (Dritek System Inc.) HKLM-x32\...\Run: [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-04-21] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [avgnt] - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [348664 2012-08-08] (Avira Operations GmbH & Co. KG) HKU\Default\...\RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation) HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [x] IMEO\acervcm.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IMEO\backupmanager.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" IMEO\itunes.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe" Startup: C:\ProgramData\Start Menu\Programs\Startup\vpngui.exe.lnk ShortcutTarget: vpngui.exe.lnk -> C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A851.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4820tg&r=27360911k306l0423z105t6691j16s HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4820tg&r=27360911k306l0423z105t6691j16s HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4820tg&r=27360911k306l0423z105t6691j16s HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4820tg&r=27360911k306l0423z105t6691j16s HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4820tg&r=27360911k306l0423z105t6691j16s HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4820tg&r=27360911k306l0423z105t6691j16s HKCU SearchScopes: DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) DPF: HKLM-x32 {E6F480FC-BD44-4CBA-B74A-89AF7842937D} hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.5.1.0.cab Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\0rdos6vz.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86224 2012-05-02] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110032 2012-05-02] (Avira Operations GmbH & Co. KG) R2 ePowerSvc; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [820768 2010-04-23] (Acer Incorporated) R2 ODDPwrSvc; C:\Program Files\Acer\Optical Drive Power Management\ODDPWRSvc.exe [171040 2010-04-22] (Acer Incorporated) S4 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2402080 2013-01-28] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98848 2012-04-25] (Avira GmbH) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132832 2012-04-27] (Avira GmbH) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [27760 2012-05-02] (Avira GmbH) R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306536 2011-03-04] () R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306536 2011-03-04] () R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [11880 2012-09-19] (TuneUp Software) U3 fwldapow; \??\C:\Users\Philipp\AppData\Local\Temp\fwldapow.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-10 19:18 - 2013-07-10 19:18 - 00000000 ____D C:\FRST 2013-07-10 19:17 - 2013-07-10 19:17 - 01776889 ____A (Farbar) C:\Users\Philipp\Desktop\FRST64.exe 2013-07-10 19:03 - 2013-07-10 19:03 - 00000538 ____A C:\Users\Philipp\Desktop\gmerlog.log 2013-07-10 18:06 - 2013-07-10 18:06 - 00071308 ____A C:\Users\Philipp\Desktop\Extras.Txt 2013-07-10 18:05 - 2013-07-10 18:05 - 00069128 ____A C:\Users\Philipp\Desktop\OTL.Txt 2013-07-10 17:52 - 2013-07-10 17:52 - 00000476 ____A C:\Users\Philipp\Desktop\defogger_disable.log 2013-07-10 17:52 - 2013-07-10 17:52 - 00000000 ____A C:\Users\Philipp\defogger_reenable 2013-07-10 17:51 - 2013-07-10 17:51 - 00001519 ____A C:\Users\Philipp\Desktop\Viren.txt 2013-07-10 17:24 - 2013-07-10 17:24 - 00602112 ____A (OldTimer Tools) C:\Users\Philipp\Desktop\OTL.exe 2013-07-10 17:24 - 2013-07-10 17:24 - 00377856 ____A C:\Users\Philipp\Desktop\gmer_2.1.19163.exe 2013-07-10 17:23 - 2013-07-10 17:24 - 00050477 ____A C:\Users\Philipp\Desktop\Defogger.exe 2013-07-09 14:20 - 2013-07-09 14:21 - 14824448 ____A C:\Users\Philipp\Downloads\5_2b_Website.ppt 2013-07-09 14:20 - 2013-07-09 14:20 - 14654976 ____A C:\Users\Philipp\Downloads\5_2a_Website.ppt 2013-06-30 22:45 - 2013-06-30 22:45 - 00000000 ____A C:\Users\Philipp\Sti_Trace.log 2013-06-29 20:49 - 2013-07-02 13:29 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Opera Software 2013-06-29 20:49 - 2013-07-02 13:29 - 00000000 ____D C:\Users\Philipp\AppData\Local\Opera Software 2013-06-27 21:59 - 2013-06-27 21:59 - 00000000 ____D C:\Users\Philipp\Desktop\Alte Klausuren ==================== One Month Modified Files and Folders ======= 2013-07-10 19:18 - 2013-07-10 19:18 - 00000000 ____D C:\FRST 2013-07-10 19:17 - 2013-07-10 19:17 - 01776889 ____A (Farbar) C:\Users\Philipp\Desktop\FRST64.exe 2013-07-10 19:03 - 2013-07-10 19:03 - 00000538 ____A C:\Users\Philipp\Desktop\gmerlog.log 2013-07-10 18:23 - 2013-02-14 19:26 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-10 18:17 - 2009-07-14 06:45 - 00009696 ___AH C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-10 18:17 - 2009-07-14 06:45 - 00009696 ___AH C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-10 18:10 - 2011-09-26 20:43 - 00000000 ____D C:\ProgramData\boost_interprocess 2013-07-10 18:09 - 2012-11-13 13:02 - 00038496 ____A C:\Windows\setupact.log 2013-07-10 18:09 - 2011-09-26 20:29 - 01842071 ____A C:\Windows\WindowsUpdate.log 2013-07-10 18:09 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-10 18:06 - 2013-07-10 18:06 - 00071308 ____A C:\Users\Philipp\Desktop\Extras.Txt 2013-07-10 18:05 - 2013-07-10 18:05 - 00069128 ____A C:\Users\Philipp\Desktop\OTL.Txt 2013-07-10 17:52 - 2013-07-10 17:52 - 00000476 ____A C:\Users\Philipp\Desktop\defogger_disable.log 2013-07-10 17:52 - 2013-07-10 17:52 - 00000000 ____A C:\Users\Philipp\defogger_reenable 2013-07-10 17:52 - 2011-09-26 20:34 - 00000000 ____D C:\Users\Philipp 2013-07-10 17:51 - 2013-07-10 17:51 - 00001519 ____A C:\Users\Philipp\Desktop\Viren.txt 2013-07-10 17:24 - 2013-07-10 17:24 - 00602112 ____A (OldTimer Tools) C:\Users\Philipp\Desktop\OTL.exe 2013-07-10 17:24 - 2013-07-10 17:24 - 00377856 ____A C:\Users\Philipp\Desktop\gmer_2.1.19163.exe 2013-07-10 17:24 - 2013-07-10 17:23 - 00050477 ____A C:\Users\Philipp\Desktop\Defogger.exe 2013-07-10 12:54 - 2012-11-16 14:02 - 00123932 ____A C:\Windows\PFRO.log 2013-07-09 14:21 - 2013-07-09 14:20 - 14824448 ____A C:\Users\Philipp\Downloads\5_2b_Website.ppt 2013-07-09 14:20 - 2013-07-09 14:20 - 14654976 ____A C:\Users\Philipp\Downloads\5_2a_Website.ppt 2013-07-07 22:27 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\FxsTmp 2013-07-02 13:29 - 2013-06-29 20:49 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Opera Software 2013-07-02 13:29 - 2013-06-29 20:49 - 00000000 ____D C:\Users\Philipp\AppData\Local\Opera Software 2013-07-02 13:26 - 2011-09-26 22:52 - 00000000 ____D C:\Users\Philipp\Documents\Sonstiges 2013-06-30 22:45 - 2013-06-30 22:45 - 00000000 ____A C:\Users\Philipp\Sti_Trace.log 2013-06-27 21:59 - 2013-06-27 21:59 - 00000000 ____D C:\Users\Philipp\Desktop\Alte Klausuren 2013-06-22 15:36 - 2011-09-26 23:40 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Dropbox 2013-06-22 15:27 - 2011-09-26 23:42 - 00000000 ___RD C:\Users\Philipp\Dropbox 2013-06-17 21:15 - 2011-09-26 22:52 - 00000000 ____D C:\Users\Philipp\Documents\Bewerbung 2013-06-12 23:53 - 2011-09-27 18:35 - 75825640 ____A (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-06-11 21:23 - 2013-02-14 19:26 - 00003822 ____A C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-06-11 21:23 - 2012-04-11 20:47 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-11 21:23 - 2011-09-26 23:24 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-06-10 20:18 - 2011-09-26 23:40 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox Files to move or delete: ==================== C:\ProgramData\FullRemove.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-08 14:05 ==================== End Of Log ============================ --- --- --- Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-07-2013 01 Ran by Philipp at 2013-07-10 19:18:36 Running from C:\Users\Philipp\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acer Backup Manager (x32 Version: 2.0.0.60) Acer Crystal Eye webcam (x32 Version: 1.0.3.0) Acer eRecovery Management (x32 Version: 4.05.3011) Acer PowerSmart Manager (x32 Version: 5.02.3003) Acer Updater (x32 Version: 1.02.3001) Acer VCM (x32 Version: 4.05.3002) Acrobat.com (x32 Version: 1.6.65) Adobe AIR (x32 Version: 1.5.0.7220) Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.224) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Reader 9.5.5 MUI (x32 Version: 9.5.5) Alcor Micro USB Card Reader (x32 Version: 1.2.17.05001) Apple Application Support (x32 Version: 2.3.2) Apple Mobile Device Support (Version: 6.0.1.3) Apple Software Update (x32 Version: 2.1.3.127) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 1.0.0.23) ATI Catalyst Install Manager (Version: 3.0.765.0) Avira Free Antivirus (x32 Version: 12.1.9.2400) Backup Manager Basic (x32 Version: 2.0.0.60) Bonjour (Version: 3.0.0.10) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center Core Implementation (x32 Version: 2010.0421.657.10561) Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0421.657.10561) Catalyst Control Center Graphics Full New (x32 Version: 2010.0421.657.10561) Catalyst Control Center Graphics Light (x32 Version: 2010.0421.657.10561) Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0421.657.10561) Catalyst Control Center InstallProxy (x32 Version: 2010.0421.657.10561) Catalyst Control Center Localization All (x32 Version: 2010.0421.657.10561) CCC Help Chinese Standard (x32 Version: 2010.0421.0656.10561) CCC Help Chinese Traditional (x32 Version: 2010.0421.0656.10561) CCC Help Czech (x32 Version: 2010.0421.0656.10561) CCC Help Danish (x32 Version: 2010.0421.0656.10561) CCC Help Dutch (x32 Version: 2010.0421.0656.10561) CCC Help English (x32 Version: 2010.0421.0656.10561) CCC Help Finnish (x32 Version: 2010.0421.0656.10561) CCC Help French (x32 Version: 2010.0421.0656.10561) CCC Help German (x32 Version: 2010.0421.0656.10561) CCC Help Greek (x32 Version: 2010.0421.0656.10561) CCC Help Hungarian (x32 Version: 2010.0421.0656.10561) CCC Help Italian (x32 Version: 2010.0421.0656.10561) CCC Help Japanese (x32 Version: 2010.0421.0656.10561) CCC Help Korean (x32 Version: 2010.0421.0656.10561) CCC Help Norwegian (x32 Version: 2010.0421.0656.10561) CCC Help Polish (x32 Version: 2010.0421.0656.10561) CCC Help Portuguese (x32 Version: 2010.0421.0656.10561) CCC Help Russian (x32 Version: 2010.0421.0656.10561) CCC Help Spanish (x32 Version: 2010.0421.0656.10561) CCC Help Swedish (x32 Version: 2010.0421.0656.10561) CCC Help Thai (x32 Version: 2010.0421.0656.10561) CCC Help Turkish (x32 Version: 2010.0421.0656.10561) ccc-core-static (x32 Version: 2010.0421.657.10561) ccc-utility64 (Version: 2010.0421.657.10561) Cisco Systems VPN Client 5.0.07.0440 (Version: 5.0.7) Citavi (x32 Version: 3.4.0.2) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32) Dropbox (HKCU Version: 2.0.22) EPSON Scan (x32) IBM SPSS Statistics 20 (Version: 20.0.0.0) Identity Card (x32 Version: 1.00.3003) Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Management Engine Components (x32 Version: 6.0.0.1179) Intel(R) Rapid Storage Technology (x32 Version: 9.6.0.1014) iTunes (Version: 11.0.0.163) Junk Mail filter update (x32 Version: 14.0.8089.726) Launch Manager (x32 Version: 4.0.7) League of Legends (x32 Version: 1.3) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Choice Guard (x32 Version: 2.0.48.0) Microsoft Office 2010 Service Pack 1 (SP1) (x32) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Home and Student 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Single Image 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Silverlight (Version: 5.1.20125.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) MSVCRT (x32 Version: 14.0.1468.721) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) ON SX130 Series Printer Uninstall Opera 12.15 (Version: 12.15.1748) Opera Stable 15.0.1147.130 (x32 Version: 15.0.1147.130) Optical Drive Power Management (x32 Version: 1.01.3007) Portal 2 (x32) PX Profile Update (x32 Version: 1.00.1.) QuickTime (x32 Version: 7.70.80.34) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6096) StarCraft II (x32 Version: 2.0.8.25604) Steam (x32 Version: 1.0.0.0) Synaptics Pointing Device Driver (Version: 14.0.6.0) Torchlight II (x32) TuneUp Utilities 2013 (x32 Version: 13.0.3020.2) TuneUp Utilities Language Pack (de-DE) (x32 Version: 10.0.4600.4) TuneUp Utilities Language Pack (de-DE) (x32 Version: 13.0.3020.2) Update for Microsoft Office 2010 (KB2494150) (x32) Update for Microsoft Office 2010 (KB2553065) (x32) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2566458) (x32) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32) Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32) Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition (x32) Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32) Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32) Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition (x32) Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32) WIDCOMM Bluetooth Software (Version: 6.3.0.4300) Windows Live Anmelde-Assistent (x32 Version: 5.000.818.5) Windows Live Call (x32 Version: 14.0.8064.0206) Windows Live Communications Platform (x32 Version: 14.0.8064.206) Windows Live Essentials (x32 Version: 14.0.8089.0726) Windows Live Essentials (x32 Version: 14.0.8089.726) Windows Live Fotogalerie (x32 Version: 14.0.8081.709) Windows Live Mail (x32 Version: 14.0.8089.0726) Windows Live Movie Maker (x32 Version: 14.0.8091.0730) Windows Live Sync (x32 Version: 14.0.8089.726) Windows Live Writer (x32 Version: 14.0.8089.0726) Windows Live-Uploadtool (x32 Version: 14.0.8014.1029) ==================== Restore Points ========================= 18-05-2013 08:00:17 Windows Update 31-05-2013 22:31:57 Geplanter Prüfpunkt 12-06-2013 21:53:17 Windows Update 08-07-2013 12:12:27 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {065C9F00-3791-4ED7-B26B-3593F69A244C} - System32\Tasks\{725BA279-3EC6-45B6-984F-3ECA3A012503} => C:\Users\Philipp\Documents\GTA3\gta3.exe No File Task: {122CF98E-5F03-46C8-99B7-227E4F970168} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation) Task: {1F2A10CA-AA94-49FB-85E9-CA6CDAE25217} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2009-07-14] (Microsoft Corporation) Task: {624A1914-59F2-42BD-8A67-9046D110ABCC} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2013\OneClick.exe [2013-01-28] (TuneUp Software) Task: {65336963-4FB5-44C1-93AF-A90FC4190466} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated) Task: {7FA65179-47C5-46D4-B5EB-8A102D08731E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-11] (Adobe Systems Incorporated) Task: {95C1829A-6566-4EC1-9229-C638560B2EA5} - System32\Tasks\{9F8CEFB5-55DD-46F1-9048-3C8AEDBF7680} => C:\Users\Philipp\Documents\GTA3\gta3.exe No File Task: {A24F354C-3DEF-44CC-B4C1-3D6CBC1F7699} - System32\Tasks\{EDDD209D-4461-416A-AE8E-7CA8473AA1A1} => C:\Users\Philipp\Downloads\GTA3\gta3.exe No File Task: {D9EC39BB-95EC-4EB3-9034-76603B8273F7} - System32\Tasks\{E2FD73E3-70D4-448C-BAE0-C6A2C5ECD8B6} => C:\Users\Philipp\Desktop\GTA3\gta3.exe No File Task: {E6C83ACA-ECD4-4CF0-BF0D-9D8E3DACEA19} - System32\Tasks\{33981785-0E06-4F4B-A4AD-72BB484A8AA0} => C:\Users\Philipp\Downloads\GTA3\gta3.exe No File Task: {EA3B40F1-7EF9-4D83-9DFD-F600EBB926D7} - System32\Tasks\{C1AC0B51-87B3-48DE-A617-FF84A47C0537} => C:\Users\Philipp\Desktop\GTA3\gta3.exe No File Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Faulty Device Manager Devices ============= Name: Cisco Systems VPN Adapter for 64-bit Windows Description: Cisco Systems VPN Adapter for 64-bit Windows Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: CVirtA Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: 1.3M WebCam Description: USB-Videogerät Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: Microsoft Service: usbvideo Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: High Definition Audio-Controller Description: High Definition Audio-Controller Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: HDAudBus Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (07/09/2013 11:33:20 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (07/09/2013 11:33:20 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"1". Die abhängige Assemblierung "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/09/2013 11:32:40 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (07/08/2013 02:07:35 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (07/08/2013 02:07:34 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"1". Die abhängige Assemblierung "UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/08/2013 02:06:53 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (07/07/2013 08:57:30 PM) (Source: Windows Backup) (User: ) Description: Die Sicherung wurde aufgrund eines Fehlers beim Schreiben am Sicherungsspeicherort "E:\" nicht abgeschlossen. Fehler: "Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)" Error: (06/30/2013 10:48:47 PM) (Source: Windows Backup) (User: ) Description: Die Sicherung wurde aufgrund eines Fehlers beim Schreiben am Sicherungsspeicherort "E:\" nicht abgeschlossen. Fehler: "Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)" Error: (06/29/2013 08:49:21 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: launcher.exe_Opera Internet Browser, Version: 15.0.1147.100, Zeitstempel: 0x51c81b64 Name des fehlerhaften Moduls: launcher_lib.dll, Version: 0.0.0.0, Zeitstempel: 0x51c81b52 Ausnahmecode: 0x80000003 Fehleroffset: 0x0001f920 ID des fehlerhaften Prozesses: 0x1254 Startzeit der fehlerhaften Anwendung: 0xlauncher.exe_Opera Internet Browser0 Pfad der fehlerhaften Anwendung: launcher.exe_Opera Internet Browser1 Pfad des fehlerhaften Moduls: launcher.exe_Opera Internet Browser2 Berichtskennung: launcher.exe_Opera Internet Browser3 Error: (06/24/2013 11:47:27 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: CrystalEye.exe, Version: 1.0.3.0, Zeitstempel: 0x4bd6e305 Name des fehlerhaften Moduls: CrystalEye.exe, Version: 1.0.3.0, Zeitstempel: 0x4bd6e305 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00014ea5 ID des fehlerhaften Prozesses: 0xce8 Startzeit der fehlerhaften Anwendung: 0xCrystalEye.exe0 Pfad der fehlerhaften Anwendung: CrystalEye.exe1 Pfad des fehlerhaften Moduls: CrystalEye.exe2 Berichtskennung: CrystalEye.exe3 System errors: ============= Error: (07/10/2013 07:04:54 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (07/10/2013 06:10:11 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (07/10/2013 06:07:47 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (07/10/2013 05:54:09 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (07/10/2013 04:55:08 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (07/10/2013 04:54:15 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (07/10/2013 00:55:16 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (07/10/2013 11:25:20 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (07/09/2013 08:57:56 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (07/09/2013 06:10:34 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Microsoft Office Sessions: ========================= Error: (07/09/2013 11:33:20 AM) (Source: SideBySide)(User: ) Description: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1"c:\program files (x86)\windows live\photo gallery\MovieMaker.Exec:\program files (x86)\windows live\photo gallery\WLMFDS.DLL8 Error: (07/09/2013 11:33:20 AM) (Source: SideBySide)(User: ) Description: UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"c:\program files (x86)\windows live\messenger\wlcsdk.exe Error: (07/09/2013 11:32:40 AM) (Source: SideBySide)(User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (07/08/2013 02:07:35 PM) (Source: SideBySide)(User: ) Description: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1"c:\program files (x86)\windows live\photo gallery\MovieMaker.Exec:\program files (x86)\windows live\photo gallery\WLMFDS.DLL8 Error: (07/08/2013 02:07:34 PM) (Source: SideBySide)(User: ) Description: UCCAPI,processorArchitecture="x86",type="win32",version="2.0.0.0"c:\program files (x86)\windows live\messenger\wlcsdk.exe Error: (07/08/2013 02:06:53 PM) (Source: SideBySide)(User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (07/07/2013 08:57:30 PM) (Source: Windows Backup)(User: ) Description: E:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006) Error: (06/30/2013 10:48:47 PM) (Source: Windows Backup)(User: ) Description: E:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006) Error: (06/29/2013 08:49:21 PM) (Source: Application Error)(User: ) Description: launcher.exe_Opera Internet Browser15.0.1147.10051c81b64launcher_lib.dll0.0.0.051c81b52800000030001f920125401ce74f95b24e7d5C:\Users\Philipp\AppData\Local\Temp\7ZipSfx.001\launcher.exeC:\Users\Philipp\AppData\Local\Temp\7ZipSfx.001\launcher_lib.dll9ba51509-e0ec-11e2-a0e0-c80aa9b181ea Error: (06/24/2013 11:47:27 PM) (Source: Application Error)(User: ) Description: CrystalEye.exe1.0.3.04bd6e305CrystalEye.exe1.0.3.04bd6e305c000000500014ea5ce801ce71246925f826C:\Program Files (x86)\Acer Crystal Eye webcam\CrystalEye.exeC:\Program Files (x86)\Acer Crystal Eye webcam\CrystalEye.exea939e877-dd17-11e2-9963-c80aa9b181ea CodeIntegrity Errors: =================================== Date: 2013-06-15 20:06:48.296 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-13 16:26:20.192 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-12 20:27:16.405 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-12 20:03:38.129 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-09 15:40:22.025 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-07 14:27:23.176 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-07 13:31:52.068 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-06 20:35:17.715 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-06-05 19:38:01.728 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-05-31 15:07:50.160 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\dsound.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 57% Total physical RAM: 3766.69 MB Available physical RAM: 1606.88 MB Total Pagefile: 7531.51 MB Available Pagefile: 5276.29 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: (Acer) (Fixed) (Total:583.07 GB) (Free:401.44 GB) NTFS (Disk=0 Partition=3) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: D389734F) Partition 1: (Not Active) - (Size=13 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=583 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Geändert von Vault (10.07.2013 um 19:15 Uhr) |
10.07.2013, 20:33 | #4 | |
/// the machine /// TB-Ausbilder | TR/Spy.ZBot.akt von Avira gefundenCombofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.07.2013, 20:58 | #5 |
| TR/Spy.ZBot.akt von Avira gefunden Alles klar, hier das ComboFix-Log: Code:
ATTFilter ComboFix 13-07-09.01 - Philipp 10.07.2013 21:47:05.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.49.1031.18.3767.2259 [GMT 2:00] ausgeführt von:: c:\users\Philipp\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\install.exe c:\programdata\FullRemove.exe c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk c:\windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A851.exe c:\windows\SysWow64\lsprst7.dll c:\windows\wininit.ini . . ((((((((((((((((((((((( Dateien erstellt von 2013-06-10 bis 2013-07-10 )))))))))))))))))))))))))))))) . . 2074-05-07 16:38 . 2006-11-21 18:48 203576 ------w- c:\program files (x86)\Microsoft Games\Age of Empires III\autopatcher2.exe 2013-07-10 19:52 . 2013-07-10 19:52 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-07-10 17:18 . 2013-07-10 17:18 -------- d-----w- C:\FRST 2013-06-29 18:49 . 2013-07-02 11:29 -------- d-----w- c:\users\Philipp\AppData\Roaming\Opera Software 2013-06-29 18:49 . 2013-07-02 11:29 -------- d-----w- c:\users\Philipp\AppData\Local\Opera Software . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-06-12 21:53 . 2011-09-27 16:35 75825640 ----a-w- c:\windows\system32\MRT.exe 2013-06-11 19:23 . 2012-04-11 18:47 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-06-11 19:23 . 2011-09-26 21:24 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-05-09 16:38 . 2013-05-09 16:39 10752 ----a-w- c:\windows\system32\E_GCINST.DLL 2013-05-09 16:38 . 2013-05-09 16:39 83968 ----a-w- c:\windows\system32\E_ID4BHJE.DLL 2013-05-09 16:38 . 2013-05-09 16:39 120320 ----a-w- c:\windows\system32\E_ILMHJE.DLL 2013-04-12 14:36 . 2013-04-24 13:07 1653096 ----a-w- c:\windows\system32\drivers\ntfs.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 130736 ----a-w- c:\users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696] "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-03-03 1300560] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-04-21 98304] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-08-08 348664] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x] R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x] R3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys;c:\windows\SYSNATIVE\DRIVERS\NETw5s64.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R4 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [x] R4 RS_Service;Raw Socket Service;c:\program files (x86)\Acer\Acer VCM\RS_Service.exe;c:\program files (x86)\Acer\Acer VCM\RS_Service.exe [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x] S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer PowerSmart Manager\ePowerSvc.exe;c:\program files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [x] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 ODDPwrSvc;Acer ODD Power Service;c:\program files\Acer\Optical Drive Power Management\ODDPWRSvc.exe;c:\program files\Acer\Optical Drive Power Management\ODDPWRSvc.exe [x] S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [x] S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x] S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x] S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys;c:\windows\SYSNATIVE\DRIVERS\igdpmd64.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2013-07-10 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-11 19:23] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 ----a-w- c:\users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 ----a-w- c:\users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 ----a-w- c:\users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-05-25 00:36 164016 ----a-w- c:\users\Philipp\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-04-09 320000] "ODDPwr"="c:\program files\Acer\Optical Drive Power Management\ODDPwr.exe" [2010-04-22 223264] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-22 10775072] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-04-22 2040352] "Acer ePower Management"="c:\program files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe" [2010-04-23 496160] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4820tg&r=27360911k306l0423z105t6691j16s uLocal Page = c:\windows\system32\blank.htm mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4820tg&r=27360911k306l0423z105t6691j16s mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4820tg&r=27360911k306l0423z105t6691j16s mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: An OneNote s&enden - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105 IE: Bild an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000 IE: Seite an &Bluetooth-Gerät senden... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm TCP: DhcpNameServer = 192.168.1.1 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) Toolbar-Locked - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CL SID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-07-10 21:55:59 ComboFix-quarantined-files.txt 2013-07-10 19:55 . Vor Suchlauf: 9 Verzeichnis(se), 430.743.461.888 Bytes frei Nach Suchlauf: 14 Verzeichnis(se), 430.482.759.680 Bytes frei . - - End Of File - - 663DA70FE8C873E142925C6335ED5330 D41D8CD98F00B204E9800998ECF8427E |
11.07.2013, 07:20 | #6 |
/// the machine /// TB-Ausbilder | TR/Spy.ZBot.akt von Avira gefunden Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST Log bitte.
__________________ --> TR/Spy.ZBot.akt von Avira gefunden |
11.07.2013, 08:36 | #7 |
| TR/Spy.ZBot.akt von Avira gefunden gesagt, getan: Code:
ATTFilter # AdwCleaner v2.304 - Datei am 11/07/2013 um 09:21:45 erstellt # Aktualisiert am 03/07/2013 von Xplode # Betriebssystem : Windows 7 Home Premium (64 bits) # Benutzer : Philipp - LAPTOP # Bootmodus : Normal # Ausgeführt unter : C:\Users\Philipp\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Ordner Gelöscht : C:\ProgramData\boost_interprocess Ordner Gelöscht : C:\ProgramData\Partner ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\Ask.com.tmp ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16476 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v [Version kann nicht ermittelt werden] Datei : C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\0rdos6vz.default\prefs.js [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [885 octets] - [11/07/2013 09:21:45] ########## EOF - C:\AdwCleaner[S1].txt - [944 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.0.7 (07.11.2013:1) OS: Windows 7 Home Premium x64 Ran by Philipp on 11.07.2013 at 9:26:14,79 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\apnstub_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\apnstub_rasmancs ~~~ Files Successfully deleted: [File] C:\eula.1028.txt Successfully deleted: [File] C:\eula.1031.txt Successfully deleted: [File] C:\eula.1033.txt Successfully deleted: [File] C:\eula.1036.txt Successfully deleted: [File] C:\eula.1040.txt Successfully deleted: [File] C:\eula.1041.txt Successfully deleted: [File] C:\eula.1042.txt Successfully deleted: [File] C:\eula.2052.txt Successfully deleted: [File] C:\install.res.1028.dll Successfully deleted: [File] C:\install.res.1031.dll Successfully deleted: [File] C:\install.res.1033.dll Successfully deleted: [File] C:\install.res.1036.dll Successfully deleted: [File] C:\install.res.1040.dll Successfully deleted: [File] C:\install.res.1041.dll Successfully deleted: [File] C:\install.res.1042.dll Successfully deleted: [File] C:\install.res.2052.dll Successfully deleted: [File] C:\install.res.3082.dll Successfully deleted: [File] C:\Windows\prefetch\APNSTUB.EXE-5B731B15.pf ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 11.07.2013 at 9:29:46,11 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-07-2013 01 Ran by Philipp (administrator) on 11-07-2013 09:33:02 Running from C:\Users\Philipp\Desktop Windows 7 Home Premium (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Acer Incorporated) C:\Program Files\Acer\Optical Drive Power Management\ODDPWRSvc.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe (Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (AlcorMicro Co., Ltd.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Acer Incorporated) C:\Program Files\Acer\Optical Drive Power Management\ODDPWR.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [320000 2009-04-09] (AlcorMicro Co., Ltd.) HKLM\...\Run: [ODDPwr] - "C:\Program Files\Acer\Optical Drive Power Management\ODDPwr.exe" [223264 2010-04-22] (Acer Incorporated) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10775072 2010-04-22] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 [2040352 2010-04-22] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-17] (Synaptics Incorporated) HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe [496160 2010-04-23] (Acer Incorporated) HKCU\...\Policies\system: [DisableRegistryTools] 0 HKCU\...\Policies\system: [DisableTaskMgr] 0 HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation) HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1300560 2010-03-03] (Dritek System Inc.) HKLM-x32\...\Run: [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-04-21] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [avgnt] - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [348664 2012-08-08] (Avira Operations GmbH & Co. KG) HKU\Default\...\RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation) HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [x] HKU\Default User\...\RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation) HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [x] ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4820tg&r=27360911k306l0423z105t6691j16s HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4820tg&r=27360911k306l0423z105t6691j16s HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4820tg&r=27360911k306l0423z105t6691j16s HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4820tg&r=27360911k306l0423z105t6691j16s SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) DPF: HKLM-x32 {E6F480FC-BD44-4CBA-B74A-89AF7842937D} hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.5.1.0.cab Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\0rdos6vz.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86224 2012-05-02] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110032 2012-05-02] (Avira Operations GmbH & Co. KG) R2 ePowerSvc; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [820768 2010-04-23] (Acer Incorporated) R2 ODDPwrSvc; C:\Program Files\Acer\Optical Drive Power Management\ODDPWRSvc.exe [171040 2010-04-22] (Acer Incorporated) S4 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2402080 2013-01-28] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98848 2012-04-25] (Avira GmbH) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132832 2012-04-27] (Avira GmbH) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [27760 2012-05-02] (Avira GmbH) R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306536 2011-03-04] () R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306536 2011-03-04] () R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [11880 2012-09-19] (TuneUp Software) S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-11 09:29 - 2013-07-11 09:29 - 00001839 ____A C:\Users\Philipp\Desktop\JRT.txt 2013-07-11 09:26 - 2013-07-11 09:26 - 00000000 ____D C:\Windows\ERUNT 2013-07-11 09:25 - 2013-07-11 09:25 - 00559306 ____A (Oleg N. Scherbakov) C:\Users\Philipp\Desktop\JRT.exe 2013-07-11 09:23 - 2013-07-11 09:23 - 00001012 ____A C:\Users\Philipp\Desktop\AdwCleaner[S1].txt 2013-07-11 09:21 - 2013-07-11 09:22 - 00001012 ____A C:\AdwCleaner[S1].txt 2013-07-11 09:20 - 2013-07-11 09:20 - 00650027 ____A C:\Users\Philipp\Desktop\adwcleaner.exe 2013-07-10 21:55 - 2013-07-10 21:55 - 00016969 ____A C:\ComboFix.txt 2013-07-10 21:45 - 2013-07-10 21:56 - 00000000 ____D C:\Qoobox 2013-07-10 21:45 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe 2013-07-10 21:45 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe 2013-07-10 21:45 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2013-07-10 21:45 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2013-07-10 21:45 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2013-07-10 21:45 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe 2013-07-10 21:45 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe 2013-07-10 21:45 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe 2013-07-10 21:44 - 2013-07-10 21:54 - 00000000 ____D C:\Windows\erdnt 2013-07-10 21:42 - 2013-07-10 21:43 - 05087643 ____R (Swearware) C:\Users\Philipp\Desktop\ComboFix.exe 2013-07-10 20:06 - 2013-07-10 20:06 - 00016905 ____A C:\Users\Philipp\Downloads\FRST.txt 2013-07-10 19:18 - 2013-07-10 19:18 - 00026428 ____A C:\Users\Philipp\Desktop\Addition.txt 2013-07-10 19:18 - 2013-07-10 19:18 - 00000000 ____D C:\FRST 2013-07-10 19:17 - 2013-07-10 19:17 - 01776889 ____A (Farbar) C:\Users\Philipp\Desktop\FRST64.exe 2013-07-10 19:03 - 2013-07-10 19:03 - 00000538 ____A C:\Users\Philipp\Desktop\gmerlog.log 2013-07-10 18:06 - 2013-07-10 18:06 - 00071308 ____A C:\Users\Philipp\Desktop\Extras.Txt 2013-07-10 18:05 - 2013-07-10 18:05 - 00069128 ____A C:\Users\Philipp\Desktop\OTL.Txt 2013-07-10 17:52 - 2013-07-10 17:52 - 00000476 ____A C:\Users\Philipp\Desktop\defogger_disable.log 2013-07-10 17:52 - 2013-07-10 17:52 - 00000000 ____A C:\Users\Philipp\defogger_reenable 2013-07-10 17:24 - 2013-07-10 17:24 - 00602112 ____A (OldTimer Tools) C:\Users\Philipp\Desktop\OTL.exe 2013-07-10 17:24 - 2013-07-10 17:24 - 00377856 ____A C:\Users\Philipp\Desktop\gmer_2.1.19163.exe 2013-07-10 17:23 - 2013-07-10 17:24 - 00050477 ____A C:\Users\Philipp\Desktop\Defogger.exe 2013-07-09 14:20 - 2013-07-09 14:21 - 14824448 ____A C:\Users\Philipp\Downloads\5_2b_Website.ppt 2013-07-09 14:20 - 2013-07-09 14:20 - 14654976 ____A C:\Users\Philipp\Downloads\5_2a_Website.ppt 2013-06-30 22:45 - 2013-06-30 22:45 - 00000000 ____A C:\Users\Philipp\Sti_Trace.log 2013-06-29 20:49 - 2013-07-02 13:29 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Opera Software 2013-06-29 20:49 - 2013-07-02 13:29 - 00000000 ____D C:\Users\Philipp\AppData\Local\Opera Software 2013-06-27 21:59 - 2013-06-27 21:59 - 00000000 ____D C:\Users\Philipp\Desktop\Alte Klausuren ==================== One Month Modified Files and Folders ======= 2013-07-11 09:32 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-11 09:31 - 2012-11-13 13:02 - 00038944 ____A C:\Windows\setupact.log 2013-07-11 09:31 - 2011-09-26 20:29 - 01888886 ____A C:\Windows\WindowsUpdate.log 2013-07-11 09:30 - 2009-07-14 06:45 - 00009696 ___AH C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-11 09:30 - 2009-07-14 06:45 - 00009696 ___AH C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-11 09:29 - 2013-07-11 09:29 - 00001839 ____A C:\Users\Philipp\Desktop\JRT.txt 2013-07-11 09:26 - 2013-07-11 09:26 - 00000000 ____D C:\Windows\ERUNT 2013-07-11 09:25 - 2013-07-11 09:25 - 00559306 ____A (Oleg N. Scherbakov) C:\Users\Philipp\Desktop\JRT.exe 2013-07-11 09:23 - 2013-07-11 09:23 - 00001012 ____A C:\Users\Philipp\Desktop\AdwCleaner[S1].txt 2013-07-11 09:23 - 2013-02-14 19:26 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-11 09:22 - 2013-07-11 09:21 - 00001012 ____A C:\AdwCleaner[S1].txt 2013-07-11 09:20 - 2013-07-11 09:20 - 00650027 ____A C:\Users\Philipp\Desktop\adwcleaner.exe 2013-07-10 22:52 - 2013-03-13 13:13 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-10 22:51 - 2011-09-26 23:46 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-07-10 22:50 - 2011-09-27 18:35 - 78185248 ____A (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-07-10 22:48 - 2009-07-14 06:54 - 00000749 __RAH C:\Windows\WindowsShell.Manifest 2013-07-10 22:48 - 2009-07-14 06:54 - 00000174 ___SH C:\Users\Public\desktop.ini 2013-07-10 22:48 - 2009-07-14 06:54 - 00000174 ___SH C:\Users\desktop.ini 2013-07-10 22:48 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries 2013-07-10 22:00 - 2012-11-16 14:02 - 00124478 ____A C:\Windows\PFRO.log 2013-07-10 21:56 - 2013-07-10 21:45 - 00000000 ____D C:\Qoobox 2013-07-10 21:56 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2013-07-10 21:55 - 2013-07-10 21:55 - 00016969 ____A C:\ComboFix.txt 2013-07-10 21:54 - 2013-07-10 21:44 - 00000000 ____D C:\Windows\erdnt 2013-07-10 21:53 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini 2013-07-10 21:43 - 2013-07-10 21:42 - 05087643 ____R (Swearware) C:\Users\Philipp\Desktop\ComboFix.exe 2013-07-10 20:06 - 2013-07-10 20:06 - 00016905 ____A C:\Users\Philipp\Downloads\FRST.txt 2013-07-10 19:18 - 2013-07-10 19:18 - 00026428 ____A C:\Users\Philipp\Desktop\Addition.txt 2013-07-10 19:18 - 2013-07-10 19:18 - 00000000 ____D C:\FRST 2013-07-10 19:17 - 2013-07-10 19:17 - 01776889 ____A (Farbar) C:\Users\Philipp\Desktop\FRST64.exe 2013-07-10 19:03 - 2013-07-10 19:03 - 00000538 ____A C:\Users\Philipp\Desktop\gmerlog.log 2013-07-10 18:06 - 2013-07-10 18:06 - 00071308 ____A C:\Users\Philipp\Desktop\Extras.Txt 2013-07-10 18:05 - 2013-07-10 18:05 - 00069128 ____A C:\Users\Philipp\Desktop\OTL.Txt 2013-07-10 17:52 - 2013-07-10 17:52 - 00000476 ____A C:\Users\Philipp\Desktop\defogger_disable.log 2013-07-10 17:52 - 2013-07-10 17:52 - 00000000 ____A C:\Users\Philipp\defogger_reenable 2013-07-10 17:52 - 2011-09-26 20:34 - 00000000 ____D C:\Users\Philipp 2013-07-10 17:24 - 2013-07-10 17:24 - 00602112 ____A (OldTimer Tools) C:\Users\Philipp\Desktop\OTL.exe 2013-07-10 17:24 - 2013-07-10 17:24 - 00377856 ____A C:\Users\Philipp\Desktop\gmer_2.1.19163.exe 2013-07-10 17:24 - 2013-07-10 17:23 - 00050477 ____A C:\Users\Philipp\Desktop\Defogger.exe 2013-07-09 14:21 - 2013-07-09 14:20 - 14824448 ____A C:\Users\Philipp\Downloads\5_2b_Website.ppt 2013-07-09 14:20 - 2013-07-09 14:20 - 14654976 ____A C:\Users\Philipp\Downloads\5_2a_Website.ppt 2013-07-07 22:27 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\FxsTmp 2013-07-02 13:29 - 2013-06-29 20:49 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Opera Software 2013-07-02 13:29 - 2013-06-29 20:49 - 00000000 ____D C:\Users\Philipp\AppData\Local\Opera Software 2013-07-02 13:26 - 2011-09-26 22:52 - 00000000 ____D C:\Users\Philipp\Documents\Sonstiges 2013-06-30 22:45 - 2013-06-30 22:45 - 00000000 ____A C:\Users\Philipp\Sti_Trace.log 2013-06-27 21:59 - 2013-06-27 21:59 - 00000000 ____D C:\Users\Philipp\Desktop\Alte Klausuren 2013-06-22 15:36 - 2011-09-26 23:40 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Dropbox 2013-06-22 15:27 - 2011-09-26 23:42 - 00000000 ___RD C:\Users\Philipp\Dropbox 2013-06-17 21:15 - 2011-09-26 22:52 - 00000000 ____D C:\Users\Philipp\Documents\Bewerbung 2013-06-11 21:23 - 2013-02-14 19:26 - 00003822 ____A C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-06-11 21:23 - 2012-04-11 20:47 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-11 21:23 - 2011-09-26 23:24 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-08 14:05 ==================== End Of Log ============================ --- --- --- |
14.07.2013, 12:08 | #8 |
/// the machine /// TB-Ausbilder | TR/Spy.ZBot.akt von Avira gefunden Normalerweise flutschen mir keine Threads durch, sorry. ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.07.2013, 12:31 | #9 |
| TR/Spy.ZBot.akt von Avira gefunden Macht doch überhaupt nichts Nein, keinerlei Probleme! Hier die Logs: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=9875bfa667d6ca47a23c693aaee2fdf8 # engine=14376 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-07-13 12:49:18 # local_time=2013-07-13 02:49:18 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=1799 16775165 100 98 6623 239143048 0 0 # compatibility_mode=5893 16776574 100 94 56622842 125349608 0 0 # scanned=238238 # found=0 # cleaned=0 # scan_time=6371 Code:
ATTFilter Results of screen317's Security Check version 0.99.68 Windows 7 x64 (UAC is enabled) Out of date service pack!! Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` TuneUp Utilities 2013 TuneUp Utilities Language Pack (de-DE) TuneUp Utilities 2013 TuneUp Utilities Language Pack (de-DE) Adobe Flash Player 11.7.700.224 Adobe Reader 9 Adobe Reader out of Date! ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-07-2013 01 Ran by Philipp (administrator) on 14-07-2013 13:18:19 Running from C:\Users\Philipp\Desktop Windows 7 Home Premium (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Acer Incorporated) C:\Program Files\Acer\Optical Drive Power Management\ODDPWRSvc.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe (Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe (AlcorMicro Co., Ltd.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Acer Incorporated) C:\Program Files\Acer\Optical Drive Power Management\ODDPWR.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe (Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [320000 2009-04-09] (AlcorMicro Co., Ltd.) HKLM\...\Run: [ODDPwr] - "C:\Program Files\Acer\Optical Drive Power Management\ODDPwr.exe" [223264 2010-04-22] (Acer Incorporated) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10775072 2010-04-22] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 [2040352 2010-04-22] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-17] (Synaptics Incorporated) HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe [496160 2010-04-23] (Acer Incorporated) HKCU\...\Policies\system: [DisableRegistryTools] 0 HKCU\...\Policies\system: [DisableTaskMgr] 0 HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-04] (Intel Corporation) HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1300560 2010-03-03] (Dritek System Inc.) HKLM-x32\...\Run: [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [98304 2010-04-21] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [avgnt] - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [348664 2012-08-08] (Avira Operations GmbH & Co. KG) HKU\Default\...\RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation) HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [x] ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4820tg&r=27360911k306l0423z105t6691j16s HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4820tg&r=27360911k306l0423z105t6691j16s HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4820tg&r=27360911k306l0423z105t6691j16s HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_4820tg&r=27360911k306l0423z105t6691j16s SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) DPF: HKLM-x32 {E6F480FC-BD44-4CBA-B74A-89AF7842937D} hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.5.1.0.cab Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Philipp\AppData\Roaming\Mozilla\Firefox\Profiles\0rdos6vz.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [86224 2012-05-02] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [110032 2012-05-02] (Avira Operations GmbH & Co. KG) R2 ePowerSvc; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [820768 2010-04-23] (Acer Incorporated) R2 ODDPwrSvc; C:\Program Files\Acer\Optical Drive Power Management\ODDPWRSvc.exe [171040 2010-04-22] (Acer Incorporated) S4 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2402080 2013-01-28] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98848 2012-04-25] (Avira GmbH) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132832 2012-04-27] (Avira GmbH) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [27760 2012-05-02] (Avira GmbH) R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306536 2011-03-04] () R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306536 2011-03-04] () R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [11880 2012-09-19] (TuneUp Software) S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-14 13:17 - 2013-07-14 13:17 - 00000994 ____A C:\Users\Philipp\Desktop\SecurityCheckup.txt 2013-07-14 13:12 - 2013-07-14 13:12 - 00890988 ____A C:\Users\Philipp\Desktop\SecurityCheck.exe 2013-07-13 14:57 - 2013-07-13 14:57 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Malwarebytes 2013-07-13 14:57 - 2013-07-13 14:57 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-07-13 13:03 - 2013-07-13 13:03 - 00000000 ___RD C:\Users\Philipp\Documents\Notes 2013-07-13 12:57 - 2013-07-13 12:57 - 02347384 ____A (ESET) C:\Users\Philipp\Downloads\esetsmartinstaller_enu (1).exe 2013-07-13 12:56 - 2013-07-13 12:57 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Philipp\Downloads\mbam-setup-1.75.0.1300.exe 2013-07-11 10:09 - 2013-07-11 10:09 - 00016905 ____A C:\Users\Philipp\Downloads\FRST (1).txt 2013-07-11 09:35 - 2013-07-13 12:54 - 00000000 ____D C:\ProgramData\boost_interprocess 2013-07-11 09:34 - 2013-07-11 09:34 - 00018478 ____A C:\Users\Philipp\Desktop\FRST2.txt 2013-07-11 09:29 - 2013-07-11 09:29 - 00001839 ____A C:\Users\Philipp\Desktop\JRT.txt 2013-07-11 09:26 - 2013-07-11 09:26 - 00000000 ____D C:\Windows\ERUNT 2013-07-11 09:25 - 2013-07-11 09:25 - 00559306 ____A (Oleg N. Scherbakov) C:\Users\Philipp\Desktop\JRT.exe 2013-07-11 09:23 - 2013-07-11 09:23 - 00001012 ____A C:\Users\Philipp\Desktop\AdwCleaner[S1].txt 2013-07-11 09:21 - 2013-07-11 09:22 - 00001012 ____A C:\AdwCleaner[S1].txt 2013-07-11 09:20 - 2013-07-11 09:20 - 00650027 ____A C:\Users\Philipp\Desktop\adwcleaner.exe 2013-07-10 21:55 - 2013-07-10 21:55 - 00016969 ____A C:\ComboFix.txt 2013-07-10 21:45 - 2013-07-10 21:56 - 00000000 ____D C:\Qoobox 2013-07-10 21:45 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe 2013-07-10 21:45 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe 2013-07-10 21:45 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2013-07-10 21:45 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2013-07-10 21:45 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2013-07-10 21:45 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe 2013-07-10 21:45 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe 2013-07-10 21:45 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe 2013-07-10 21:44 - 2013-07-10 21:54 - 00000000 ____D C:\Windows\erdnt 2013-07-10 21:42 - 2013-07-10 21:43 - 05087643 ____R (Swearware) C:\Users\Philipp\Desktop\ComboFix.exe 2013-07-10 20:06 - 2013-07-10 20:06 - 00016905 ____A C:\Users\Philipp\Downloads\FRST.txt 2013-07-10 19:18 - 2013-07-10 19:18 - 00026428 ____A C:\Users\Philipp\Desktop\Addition.txt 2013-07-10 19:18 - 2013-07-10 19:18 - 00000000 ____D C:\FRST 2013-07-10 19:17 - 2013-07-10 19:17 - 01776889 ____A (Farbar) C:\Users\Philipp\Desktop\FRST64.exe 2013-07-10 19:03 - 2013-07-10 19:03 - 00000538 ____A C:\Users\Philipp\Desktop\gmerlog.log 2013-07-10 18:06 - 2013-07-10 18:06 - 00071308 ____A C:\Users\Philipp\Desktop\Extras.Txt 2013-07-10 18:05 - 2013-07-10 18:05 - 00069128 ____A C:\Users\Philipp\Desktop\OTL.Txt 2013-07-10 17:52 - 2013-07-10 17:52 - 00000476 ____A C:\Users\Philipp\Desktop\defogger_disable.log 2013-07-10 17:52 - 2013-07-10 17:52 - 00000000 ____A C:\Users\Philipp\defogger_reenable 2013-07-10 17:24 - 2013-07-10 17:24 - 00602112 ____A (OldTimer Tools) C:\Users\Philipp\Desktop\OTL.exe 2013-07-10 17:24 - 2013-07-10 17:24 - 00377856 ____A C:\Users\Philipp\Desktop\gmer_2.1.19163.exe 2013-07-10 17:23 - 2013-07-10 17:24 - 00050477 ____A C:\Users\Philipp\Desktop\Defogger.exe 2013-07-09 14:20 - 2013-07-09 14:21 - 14824448 ____A C:\Users\Philipp\Downloads\5_2b_Website.ppt 2013-07-09 14:20 - 2013-07-09 14:20 - 14654976 ____A C:\Users\Philipp\Downloads\5_2a_Website.ppt 2013-06-30 22:45 - 2013-06-30 22:45 - 00000000 ____A C:\Users\Philipp\Sti_Trace.log 2013-06-29 20:49 - 2013-07-02 13:29 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Opera Software 2013-06-29 20:49 - 2013-07-02 13:29 - 00000000 ____D C:\Users\Philipp\AppData\Local\Opera Software ==================== One Month Modified Files and Folders ======= 2013-07-14 13:17 - 2013-07-14 13:17 - 00000994 ____A C:\Users\Philipp\Desktop\SecurityCheckup.txt 2013-07-14 13:16 - 2011-09-26 20:29 - 01984856 ____A C:\Windows\WindowsUpdate.log 2013-07-14 13:12 - 2013-07-14 13:12 - 00890988 ____A C:\Users\Philipp\Desktop\SecurityCheck.exe 2013-07-14 12:36 - 2009-07-14 06:45 - 00009696 ___AH C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-14 12:36 - 2009-07-14 06:45 - 00009696 ___AH C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-14 12:29 - 2012-11-13 13:02 - 00039314 ____A C:\Windows\setupact.log 2013-07-14 12:29 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-13 17:23 - 2013-02-14 19:26 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-13 14:57 - 2013-07-13 14:57 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Malwarebytes 2013-07-13 14:57 - 2013-07-13 14:57 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-07-13 13:03 - 2013-07-13 13:03 - 00000000 ___RD C:\Users\Philipp\Documents\Notes 2013-07-13 12:57 - 2013-07-13 12:57 - 02347384 ____A (ESET) C:\Users\Philipp\Downloads\esetsmartinstaller_enu (1).exe 2013-07-13 12:57 - 2013-07-13 12:56 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\Philipp\Downloads\mbam-setup-1.75.0.1300.exe 2013-07-13 12:54 - 2013-07-11 09:35 - 00000000 ____D C:\ProgramData\boost_interprocess 2013-07-13 12:53 - 2012-11-16 14:02 - 00127318 ____A C:\Windows\PFRO.log 2013-07-11 19:41 - 2011-09-26 20:34 - 00000000 ____D C:\Users\Philipp 2013-07-11 10:09 - 2013-07-11 10:09 - 00016905 ____A C:\Users\Philipp\Downloads\FRST (1).txt 2013-07-11 09:34 - 2013-07-11 09:34 - 00018478 ____A C:\Users\Philipp\Desktop\FRST2.txt 2013-07-11 09:29 - 2013-07-11 09:29 - 00001839 ____A C:\Users\Philipp\Desktop\JRT.txt 2013-07-11 09:26 - 2013-07-11 09:26 - 00000000 ____D C:\Windows\ERUNT 2013-07-11 09:25 - 2013-07-11 09:25 - 00559306 ____A (Oleg N. Scherbakov) C:\Users\Philipp\Desktop\JRT.exe 2013-07-11 09:23 - 2013-07-11 09:23 - 00001012 ____A C:\Users\Philipp\Desktop\AdwCleaner[S1].txt 2013-07-11 09:22 - 2013-07-11 09:21 - 00001012 ____A C:\AdwCleaner[S1].txt 2013-07-11 09:20 - 2013-07-11 09:20 - 00650027 ____A C:\Users\Philipp\Desktop\adwcleaner.exe 2013-07-10 22:52 - 2013-03-13 13:13 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-10 22:51 - 2011-09-26 23:46 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-07-10 22:50 - 2011-09-27 18:35 - 78185248 ____A (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-07-10 22:48 - 2009-07-14 06:54 - 00000749 __RAH C:\Windows\WindowsShell.Manifest 2013-07-10 22:48 - 2009-07-14 06:54 - 00000174 ___SH C:\Users\Public\desktop.ini 2013-07-10 22:48 - 2009-07-14 06:54 - 00000174 ___SH C:\Users\desktop.ini 2013-07-10 22:48 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries 2013-07-10 21:56 - 2013-07-10 21:45 - 00000000 ____D C:\Qoobox 2013-07-10 21:56 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2013-07-10 21:55 - 2013-07-10 21:55 - 00016969 ____A C:\ComboFix.txt 2013-07-10 21:54 - 2013-07-10 21:44 - 00000000 ____D C:\Windows\erdnt 2013-07-10 21:53 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini 2013-07-10 21:43 - 2013-07-10 21:42 - 05087643 ____R (Swearware) C:\Users\Philipp\Desktop\ComboFix.exe 2013-07-10 20:06 - 2013-07-10 20:06 - 00016905 ____A C:\Users\Philipp\Downloads\FRST.txt 2013-07-10 19:18 - 2013-07-10 19:18 - 00026428 ____A C:\Users\Philipp\Desktop\Addition.txt 2013-07-10 19:18 - 2013-07-10 19:18 - 00000000 ____D C:\FRST 2013-07-10 19:17 - 2013-07-10 19:17 - 01776889 ____A (Farbar) C:\Users\Philipp\Desktop\FRST64.exe 2013-07-10 19:03 - 2013-07-10 19:03 - 00000538 ____A C:\Users\Philipp\Desktop\gmerlog.log 2013-07-10 18:06 - 2013-07-10 18:06 - 00071308 ____A C:\Users\Philipp\Desktop\Extras.Txt 2013-07-10 18:05 - 2013-07-10 18:05 - 00069128 ____A C:\Users\Philipp\Desktop\OTL.Txt 2013-07-10 17:52 - 2013-07-10 17:52 - 00000476 ____A C:\Users\Philipp\Desktop\defogger_disable.log 2013-07-10 17:52 - 2013-07-10 17:52 - 00000000 ____A C:\Users\Philipp\defogger_reenable 2013-07-10 17:24 - 2013-07-10 17:24 - 00602112 ____A (OldTimer Tools) C:\Users\Philipp\Desktop\OTL.exe 2013-07-10 17:24 - 2013-07-10 17:24 - 00377856 ____A C:\Users\Philipp\Desktop\gmer_2.1.19163.exe 2013-07-10 17:24 - 2013-07-10 17:23 - 00050477 ____A C:\Users\Philipp\Desktop\Defogger.exe 2013-07-09 14:21 - 2013-07-09 14:20 - 14824448 ____A C:\Users\Philipp\Downloads\5_2b_Website.ppt 2013-07-09 14:20 - 2013-07-09 14:20 - 14654976 ____A C:\Users\Philipp\Downloads\5_2a_Website.ppt 2013-07-07 22:27 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\FxsTmp 2013-07-02 13:29 - 2013-06-29 20:49 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Opera Software 2013-07-02 13:29 - 2013-06-29 20:49 - 00000000 ____D C:\Users\Philipp\AppData\Local\Opera Software 2013-07-02 13:26 - 2011-09-26 22:52 - 00000000 ____D C:\Users\Philipp\Documents\Sonstiges 2013-06-30 22:45 - 2013-06-30 22:45 - 00000000 ____A C:\Users\Philipp\Sti_Trace.log 2013-06-22 15:36 - 2011-09-26 23:40 - 00000000 ____D C:\Users\Philipp\AppData\Roaming\Dropbox 2013-06-22 15:27 - 2011-09-26 23:42 - 00000000 ___RD C:\Users\Philipp\Dropbox 2013-06-17 21:15 - 2011-09-26 22:52 - 00000000 ____D C:\Users\Philipp\Documents\Bewerbung ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-08 14:05 ==================== End Of Log ============================ --- --- --- |
14.07.2013, 12:52 | #10 |
/// the machine /// TB-Ausbilder | TR/Spy.ZBot.akt von Avira gefunden Adobe und Windows updaten Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.07.2013, 14:25 | #11 |
| TR/Spy.ZBot.akt von Avira gefunden Probleme sind bisher keine aufgetreten, die Updates werde ich gleich durchführen. Ich denke du kannst den Thread aus den Abos löschen! Vielen, vielen Dank für deine Unterstützung! |
14.07.2013, 18:41 | #12 |
/// the machine /// TB-Ausbilder | TR/Spy.ZBot.akt von Avira gefunden Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu TR/Spy.ZBot.akt von Avira gefunden |
acer, anwaltschaft, appdata, avira, cache, datei, gmer, gmx, infiziert, live, mail, microsoft, namen, nicht mehr, opera, pferd, rechnung, suche, system, trojaner, trojanische, trojanische pferd, warnung, windows, windows live, windows live mail |